Elium · Vulnerability Disclosure
Elium Vulnerability Disclosure
Vulnerability disclosure
Elium runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.
CompanySoftware-as-a-ServiceKnowledge-ManagementKnowledge BaseEnterprise SearchAI SearchGraphQLMCPCollaborationDocumentationRAGEurope
Program: Hackerone
Disclosure Policy
Security Contact
Contact
security@elium.com
Source
Vulnerability Disclosure
generated: '2026-08-17'
method: searched
probe: true
source: https://elium.com/trust/controls
policy: []
policy_published: false
contact: [security@elium.com]
contact_url: https://elium.com/trust/controls
bug_bounty: null
finding: >-
Elium publishes a security contact and a public security-controls page, but NO responsible-disclosure
policy and NO bug-bounty programme. security@elium.com is presented as a general security-team mailbox
("handles vendor reviews, RFPs, audits, and architecture questions"), not as a vulnerability intake with
scope, safe-harbour terms, or response targets. A researcher has an address to write to and nothing that
tells them the rules. Recorded honestly: a reachable channel, an absent programme.
what_exists:
- {item: security contact, value: 'security@elium.com', source: 'https://elium.com/trust'}
- {item: public security-controls page, value: 'https://elium.com/trust/controls'}
- item: third-party penetration testing
value: >-
"Penetration tests are conducted regularly by independent third parties and vulnerability scans are
automated. Findings are assessed and remediated per defined SLAs."
source: https://elium.com/trust/controls
- item: penetration-test reports
value: 2025 and 2024 reports listed as documents available on request
source: https://elium.com/trust
- item: incident-response programme with acknowledgement/resolution SLAs
source: https://elium.com/trust/controls
what_is_missing:
- No /.well-known/security.txt (RFC 9116) on elium.com or api.elium.com - both 404.
- No responsible-disclosure or vulnerability-disclosure page - /security and /responsible-disclosure both 404.
- No HackerOne, Bugcrowd, Intigriti, YesWeHack or self-hosted bounty programme found.
- No stated scope, safe harbour, PGP key, or researcher response-time commitment.
false_positive_rejected:
url: https://help.elium.com/.well-known/security.txt
http_status: 200
content_type: text/plain
verdict: rejected
reason: >-
This is INTERCOM's security.txt, served because Elium's help centre is Intercom-hosted. Its own Canonical
field is https://app.intercom.com/.well-known/security.txt and its contacts are bugcrowd.com/intercom and
security@intercom.com. Crediting it to Elium would attribute another company's bug-bounty programme to
them, so it is deliberately not saved and no SecurityTxt pointer is wired.
evidence:
- {source: 'https://elium.com/trust', http_status: 200, kind: security-contact, probed: '2026-08-17'}
- {source: 'https://elium.com/trust/controls', http_status: 200, kind: security-policy-page, probed: '2026-08-17'}
- {source: 'https://elium.com/.well-known/security.txt', http_status: 404, kind: absent, probed: '2026-08-17'}
- {source: 'https://api.elium.com/.well-known/security.txt', http_status: 404, kind: absent, probed: '2026-08-17'}
- {source: 'https://elium.com/security', http_status: 404, kind: absent, probed: '2026-08-17'}
- {source: 'https://elium.com/responsible-disclosure', http_status: 404, kind: absent, probed: '2026-08-17'}
recommendation: >-
Publishing /.well-known/security.txt on elium.com pointing at security@elium.com and a short disclosure
page would cost Elium almost nothing and is the single cheapest security-transparency gap on this profile.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/elium-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.